memtest86+ will not stop unless it is given the command to do so. If the system rebooted while running memtest86+, a hardware error likely occurred to cause it (or a power outage).
Code:
-
Loading Dump File [D:\Kingston\BSODDmpFiles\Demonocracy\Minidump\040812-13930-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17727.x86fre.win7sp1_gdr.111118-2330
Machine Name:
Kernel base = 0x82c50000 PsLoadedModuleList = 0x82d994d0
Debug session time: Sun Apr 8 05:05:35.463 2012 (UTC - 6:00)
System Uptime: 0 days 0:00:14.539
Loading Kernel Symbols
...............................................................
................................................................
...........
Loading User Symbols
Loading unloaded module list
....
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
WINLOGON_FATAL_ERROR (c000021a)
The Winlogon process terminated unexpectedly.
Arguments:
Arg1: 9aeb2e50, String that identifies the problem.
Arg2: 00000000, Error Code.
Arg3: c0000001
Arg4: 00100524
Debugging Details:
------------------
BUGCHECK_STR: 0xc000021a_0
ERROR_CODE: (NTSTATUS) 0xc000021a - {Fatal System Error} The %hs system process terminated unexpectedly with a status of 0x%08x (0x%08x 0x%08x). The system has been shut down.
EXCEPTION_CODE: (NTSTATUS) 0xc000021a - {Fatal System Error} The %hs system process terminated unexpectedly with a status of 0x%08x (0x%08x 0x%08x). The system has been shut down.
EXCEPTION_PARAMETER1: 9aeb2e50
EXCEPTION_PARAMETER2: 00000000
EXCEPTION_PARAMETER3: c0000001
EXCEPTION_PARAMETER4: 100524
ADDITIONAL_DEBUG_TEXT: initial session process or
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 82f29427 to 82d2ef04
STACK_TEXT:
8d0418e4 82f29427 0000004c c000021a 8d04196c nt!KeBugCheckEx+0x1e
8d041934 82f7b9f1 00000001 0000004c c000021a nt!PoShutdownBugCheck+0x81
8d041af4 82e28dae c000021a 00000004 00000001 nt!ExpSystemErrorHandler+0x567
8d041ca4 82e2820e c000021a 00000004 00000001 nt!ExpRaiseHardError+0xbf
8d041d14 82c8e28a c000021a 00000004 00000001 nt!NtRaiseHardError+0x11a
8d041d14 776d7094 c000021a 00000004 00000001 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
0048f500 00000000 00000000 00000000 00000000 0x776d7094
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiFastCallEntry+12a
82c8e28a f6456c01 test byte ptr [ebp+6Ch],1
SYMBOL_STACK_INDEX: 5
SYMBOL_NAME: nt!KiFastCallEntry+12a
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrpamp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4ec79850
FAILURE_BUCKET_ID: 0xc000021a_0_nt!KiFastCallEntry+12a
BUCKET_ID: 0xc000021a_0_nt!KiFastCallEntry+12a
Followup: MachineOwner
---------
-
Loading Dump File [D:\Kingston\BSODDmpFiles\Demonocracy\Minidump\040812-31590-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17727.x86fre.win7sp1_gdr.111118-2330
Machine Name:
Kernel base = 0x82c53000 PsLoadedModuleList = 0x82d9c4d0
Debug session time: Sat Apr 7 18:19:38.924 2012 (UTC - 6:00)
System Uptime: 0 days 0:52:14.673
Loading Kernel Symbols
...............................................................
................................................................
........................................
Loading User Symbols
Loading unloaded module list
.....
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
be among the most commonly seen crashes.
Arguments:
Arg1: 00000081, MmMapLockedPages called without MDL_MAPPING_CAN_FAIL
Arg2: a143e378, MDL address.
Arg3: 00000082, MDL flags.
Arg4: 00000000, 0.
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for mcdbus.sys
*** ERROR: Module load completed but symbols could not be loaded for mcdbus.sys
BUGCHECK_STR: 0xc4_81
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 82f89f03 to 82d31f04
STACK_TEXT:
87f1b958 82f89f03 000000c4 00000081 a143e378 nt!KeBugCheckEx+0x1e
87f1b978 82f96edb a143e378 a145e598 a07c4c20 nt!VerifierBugCheckIfAppropriate+0x30
87f1b990 8fc2c33f a143e378 00000000 a07c4c20 nt!VerifierMmMapLockedPages+0x3e
WARNING: Stack unwind information not available. Following frames may be wrong.
87f1bc40 833def3a 69d39500 87f1bcac 87f1bc84 mcdbus+0x1533f
87f1bc5c 833dc51d 962c6cc0 00000000 00000018 cdrom!RequestHandleGetDriveGeometry+0x40
87f1bcb0 833dc85d 962c6cc0 7a28beb0 953c6f80 cdrom!RequestProcessSerializedIoctl+0x518
87f1bcc4 85450042 6ac39078 9499efe0 953c6f80 cdrom!IoctlWorkItemRoutine+0x4b
87f1bce0 854500aa 9182a2d8 87f1bd00 82e67524 Wdf01000!FxWorkItem::WorkItemHandler+0xad
87f1bcec 82e67524 9182a2d8 953c6f80 85391d48 Wdf01000!FxWorkItem::WorkItemThunk+0x19
87f1bd00 82cd0aab 9499efe0 00000000 85391d48 nt!IopProcessWorkItem+0x23
87f1bd50 82e5c022 00000001 af7ecd0e 00000000 nt!ExpWorkerThread+0x10d
87f1bd90 82d04219 82cd099e 00000001 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
STACK_COMMAND: kb
FOLLOWUP_IP:
mcdbus+1533f
8fc2c33f ?? ???
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: mcdbus+1533f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: mcdbus
IMAGE_NAME: mcdbus.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 49a3cf05
FAILURE_BUCKET_ID: 0xc4_81_VRF_mcdbus+1533f
BUCKET_ID: 0xc4_81_VRF_mcdbus+1533f
Followup: MachineOwner
---------
- Indicates data corruption.
- Caused by MagicISO.
Disable Verifier for now: Start Menu -> All Programs -> Accessories -> Right click Command Prompt -> Run as administrator -> Type the following command and then Enter:
verifier /reset
-> Restart your computer.
Do you have the latest version of MagicISO? If you do not, I would recommend uninstalling your current version and downloading the latest version. It may provide more stability.
For the data corruption...
- Run Disk Check with both boxes checked for all HDDs and with Automatically fix file system errors checked for all SSDs. Post back your logs for the checks after finding them using Check Disk (chkdsk) - Read Event Viewer Log.
For any drives that do not give the message:
Windows has checked the file system and found no problems
run disk check again as above. In other words, if it says:
Windows has made corrections to the file system
after running the disk check, run the disk check again.
- Run SFC /SCANNOW Command - System File Checker up to three times to fix all errors with a restart in between each. Post back if it continues to show errors after a fourth run or if the first run comes back with no integrity violations.